Ad

CVE-2026-40077

LOW CVSS 3.1: 3.1 EPSS 0.06%
Updated Apr 17, 2026
Beszel
Parameter Value
CVSS 3.1 (LOW)
Affected Versions before 0.18.7
Fixed In 0.18.7
Type CWE-184
Vendor Beszel
Public PoC No

Beszel is a server monitoring platform. Prior to 0.18.7, some API endpoints in the Beszel hub accept a user-supplied system ID and proceed without further checks that the user should have access to that system. As a result, any authenticated user can access these routes for any system if they know the system's ID.

System IDs are random 15 character alphanumeric strings, and are not exposed to all users. However, it is theoretically possible for an authenticated user to enumerate a valid system ID via web API. To use the containers endpoints, the user would also need to enumerate a container ID, which is 12 digit hexadecimal string.

This vulnerability is fixed in 0.18.7.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
High
Difficult to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Beszel Beszel
cpe:2.3:a:beszel:beszel:*:*:*:*:*:*:*:*
0.18.7